The key stays protected, the application decides
The HSM protects a signing key within its intended boundary; it does not itself decide whether a software package should be approved for release. That is why we tie signing calls to identified applications, permissions and approvals. In code signing, the artifact and the approval are linked together, so that later changes are detectable. The CA software and the HSM provider must both support the algorithm and key access method in use. Trust stores, status checking and renewal are tested with representative counterparts.


